You are on page 1of 4

Overview of Processing Activities Cover Page

under Article 30(1) GDPR


Controller
Controller Details
Name and contact information of the individual / legal person / agency / body etc.
Name
Street
ZIP code
City
Telephone
E-Mail address
Internet URL

If applicable, Details of Joint Controllers


Name
Street
ZIP code
City
Telephone
E-Mail address

Details of Controller’s Representative


Name and contact information of the individual / legal person / agency / body etc.
Name
Street
ZIP code
City
Telephone
E-Mail address

Details of the Data Protection Officer* (if external, provide street address)
* to the extent a DPO has been appointed under Article 37 GDPR
Form of address Title (e.g. Dr.)
Surname, First Name
Street
ZIP code
City
Telephone
E-Mail Address

Page 1 of 3
Processing Activity: Index No.:
Title: _____________________ _____
Commencement date: Date of most recent modification:

Responsible
Department
Point of Contact
Telephone
E-Mail Address
(Art. 30(1)(2)(a) GDPR)

Purposes of the
Processing (Art. 30(1)(2)
(b) GDPR)

Optional:
Name of the process(es)
employed

Description of the Employees


Categories of affected Applicants
Data Subjects
Suppliers
(Art. 30(1)(2)(c) GDPR)
Customers
Patients

Description of the
Categories of Personal
Data
(Art. 30(1)(2)(c) GDPR)

Special Categories of Personal Data (Art. 9 GDPR):

Page 1 of 3
Categories of Recipients Internal Recipients (authorized users / users with access rights)
to whom Personal Data Department / Function
have been – or will be -
disclosed
(Art. 30(1)(2)(d) GDPR)

External Recipients
Categories of Recipients

Third Countries or International Organizations (identify by category)

If applicable, Transfers Transfers do not occur and are not planned to occur
of Personal Data to a
Third Country or
Transfers are made as follows:
International
Organization
(Art. 30(1)(2)(e) GDPR)

Identification of Specific
Transfer Recipients Third Country or International Organization (identify by name)

To the extent that Documentation of Sufficient Safeguards for Transfers


Transfers fall under Art.
49(1) para. 2 GDPR
[Note: These are one-
time transfers affecting
a “limited number” of
individuals made on the
basis of “compelling
legitimate interests”]:

Retention/Deletion
Periods for the Various
Categories of Personal
Data
(Art. 30(1)(2)(f) GDPR)

Technical and Organizational Measures (TOMs) implemented to ensure Information Security under Art.
32(1) GDPR
(Art. 30(1)(2)(g) GDPR)
For guidance on describing Information Security TOMs, see points 6.7 and 6.8 of the Data Protection
Conferences “Tips for the Index of Processing Activities” (available [in German] here)
Page 1 of 3
……………………………… …………………… ...........................................................
Controller Date Signature

Page 1 of 3

You might also like